Raja Grewal
|
759aee8150
|
Provide option to disable user namespaces
|
2024-08-16 22:54:57 +10:00 |
|
Patrick Schleizer
|
e962153f84
|
bumped changelog version
|
2024-08-16 08:38:12 +00:00 |
|
Patrick Schleizer
|
40b12f5a2a
|
Merge remote-tracking branch 'github-kicksecure/master'
|
2024-08-16 04:30:29 -04:00 |
|
Patrick Schleizer
|
305467c652
|
Merge pull request #245 from raja-grewal/blacklist_to_disable
Update `/etc/modprobe.d/*`
|
2024-08-16 04:25:43 -04:00 |
|
Patrick Schleizer
|
12296c68dc
|
Merge remote-tracking branch 'github-kicksecure/master'
|
2024-08-16 04:22:43 -04:00 |
|
Patrick Schleizer
|
036bcea4e6
|
Merge pull request #262 from raja-grewal/docs
Miscellaneous updates to presentation
|
2024-08-16 04:20:32 -04:00 |
|
raja-grewal
|
81bf7a8f90
|
Merge branch 'Kicksecure:master' into docs
|
2024-08-16 16:57:01 +10:00 |
|
Patrick Schleizer
|
ef60c5b153
|
Merge pull request #249 from raja-grewal/binfmt_misc
Disallow registering interpreters for miscellaneous binary formats
|
2024-08-16 02:43:57 -04:00 |
|
Raja Grewal
|
cea8e75378
|
Consistent formating
|
2024-08-16 14:55:22 +10:00 |
|
Raja Grewal
|
84376d23fc
|
Add details on ASLR and move to user space section
|
2024-08-16 13:39:11 +10:00 |
|
Raja Grewal
|
a132980023
|
Update README.md
|
2024-08-16 13:24:25 +10:00 |
|
Raja Grewal
|
9212a4e937
|
Typos
|
2024-08-16 13:12:07 +10:00 |
|
Raja Grewal
|
e3a3207a44
|
Clarify DMA hardening
|
2024-08-16 12:41:36 +10:00 |
|
raja-grewal
|
be9308e490
|
Merge branch 'Kicksecure:master' into docs
|
2024-08-16 11:45:43 +10:00 |
|
Patrick Schleizer
|
4bc12b07b4
|
bumped changelog version
|
2024-08-15 17:51:18 +00:00 |
|
Patrick Schleizer
|
9e61e37c17
|
Merge remote-tracking branch 'github-kicksecure/master'
|
2024-08-15 13:47:33 -04:00 |
|
Patrick Schleizer
|
dfd1c97168
|
Merge pull request #248 from raja-grewal/secure_redirects
Re-enable (default) `secure_redirects` for ICMP redirect messages
|
2024-08-15 13:46:30 -04:00 |
|
Raja Grewal
|
b552b92401
|
Add references on fs.binfmt_misc.status
|
2024-08-15 11:54:21 +10:00 |
|
Raja Grewal
|
326d82a9be
|
Revert "Provide optional sysctl fs.binfmt_misc.status=0 "
This reverts commit debd7a7b7a .
|
2024-08-15 11:46:56 +10:00 |
|
Raja Grewal
|
73db68dbf9
|
Add details on KFENCE
|
2024-08-09 14:27:30 +10:00 |
|
Raja Grewal
|
f8fa89b245
|
Add details on tcp_timestamps
|
2024-08-09 14:21:59 +10:00 |
|
Raja Grewal
|
3456f1c1d7
|
Minor consistency update in README.md
|
2024-08-09 13:39:25 +10:00 |
|
Raja Grewal
|
15c638acad
|
Add reference on RDRAND
|
2024-08-09 13:36:47 +10:00 |
|
Raja Grewal
|
077bc48a26
|
Add reference on rp_filter
|
2024-08-09 13:35:33 +10:00 |
|
Raja Grewal
|
d8bcec881f
|
Add some notices for future Debian 13 rebase
|
2024-08-09 13:33:32 +10:00 |
|
Raja Grewal
|
0b0683499a
|
Consistent line length formatting
|
2024-08-09 13:30:39 +10:00 |
|
Raja Grewal
|
e5a38fc856
|
Typo
|
2024-08-09 13:30:15 +10:00 |
|
Raja Grewal
|
a5373afc55
|
Details on disabled fbdev kernel modules
|
2024-08-07 14:44:14 +10:00 |
|
Raja Grewal
|
e98dc8c4f8
|
Update notifications for disabled kernel modules
|
2024-08-07 14:14:47 +10:00 |
|
Raja Grewal
|
50fa721fd5
|
Update docs regarding Intel module disabling
|
2024-08-07 14:01:49 +10:00 |
|
Raja Grewal
|
ec3038c7bc
|
Clarify secure_redirects
|
2024-08-07 13:48:53 +10:00 |
|
Raja Grewal
|
debd7a7b7a
|
Provide optional sysctl fs.binfmt_misc.status=0
|
2024-08-07 13:33:44 +10:00 |
|
Patrick Schleizer
|
89e816dda6
|
bumped changelog version
|
2024-08-06 14:01:39 +00:00 |
|
Patrick Schleizer
|
967f9e257b
|
Merge remote-tracking branch 'github-kicksecure/master'
|
2024-08-06 09:57:56 -04:00 |
|
Patrick Schleizer
|
a25aaf900a
|
Merge pull request #260 from raja-grewal/vdso32
Enable `vdso32=0`
|
2024-08-06 09:55:20 -04:00 |
|
Patrick Schleizer
|
6bc039a430
|
Merge pull request #259 from raja-grewal/kfence
Enable `kfence.sample_interval=100`
|
2024-08-06 09:52:56 -04:00 |
|
Patrick Schleizer
|
ce60d5615f
|
Merge pull request #258 from raja-grewal/legacy_tiocsti
Enable `dev.tty.legacy_tiocsti=0`
|
2024-08-06 09:48:08 -04:00 |
|
Patrick Schleizer
|
b0278428a7
|
Merge pull request #257 from raja-grewal/slab_debug
Enable `slab_debug=FZ`
|
2024-08-06 09:39:04 -04:00 |
|
Raja Grewal
|
8559079312
|
Enable vdso32=0
|
2024-08-05 15:10:02 +10:00 |
|
Raja Grewal
|
d102ec1997
|
Enable kfence.sample_interval=100
|
2024-08-05 15:07:56 +10:00 |
|
Raja Grewal
|
c0d140f221
|
Enable dev.tty.legacy_tiocsti=0
|
2024-08-05 15:06:34 +10:00 |
|
Raja Grewal
|
aa34d86598
|
Enable slab_debug=FZ
|
2024-08-05 14:27:17 +10:00 |
|
Raja Grewal
|
4f7f820160
|
Add reference
|
2024-08-05 14:16:33 +10:00 |
|
Patrick Schleizer
|
fa9091869d
|
Merge remote-tracking branch 'github-kicksecure/master'
|
2024-08-04 16:20:36 -04:00 |
|
Patrick Schleizer
|
725118c575
|
Merge pull request #243 from raja-grewal/namespaces
Restrict unprivileged user namespaces
|
2024-08-04 16:19:52 -04:00 |
|
Patrick Schleizer
|
06f0c27128
|
Merge remote-tracking branch 'github-kicksecure/master'
|
2024-08-04 16:15:01 -04:00 |
|
Patrick Schleizer
|
6d97408a6d
|
Merge pull request #255 from raja-grewal/SLUB
Restore option to enable `slub_debug=FZ`
|
2024-08-04 16:11:46 -04:00 |
|
Patrick Schleizer
|
8abc5ae8f0
|
Merge remote-tracking branch 'github-kicksecure/master'
|
2024-08-04 16:09:52 -04:00 |
|
Patrick Schleizer
|
eab66dad09
|
Merge pull request #254 from raja-grewal/patch
Updates to kernel and `sysctl` hardening
|
2024-08-04 16:08:32 -04:00 |
|
Raja Grewal
|
6f14d68cdc
|
Update legacy name slub_debug -> slab_debug
|
2024-08-03 15:12:15 +10:00 |
|